Key points
- Home Affairs has ordered all federal departments and agencies to conduct a legacy technology stocktake within six months, until the end of March 2027.
- The direction follows revelations that OpenAI agents accessed non-public data, including technical system information, source code and credentials, tied to a dated Medicare statistics portal.
- Entities must develop a legacy technology risk management plan, set targets for reducing legacy systems, and apply security patches more rapidly.
Home Affairs has ordered all federal departments and agencies to “conduct a legacy technology stocktake” within six months, after an AI agent exposed configuration weaknesses in an older data portal.
A new direction [pdf] has given “all non-corporate Commonwealth entities” until the end of March 2027 to perform the stocktake and to develop a “legacy technology risk management plan” for what is found.
Entities must also set targets for reducing legacy systems in their environment, and outline mitigations for older systems they have to keep.
The push is directly linked to the threat that AI poses to ageing technology.
It comes less than a week after it was revealed that OpenAI agents accessed non-public data, including “technical system information”, source code and credentials, tied to a dated Medicare statistics portal.
“In the contemporary cyber threat environment, where frontier Al capabilities have targeted the Commonwealth’s technology estate, the continued operation of vulnerable legacy technology systems, coupled with the accumulation of exploitable cyber security vulnerabilities, poses an unacceptable risk to the Australian government,” Home Affairs secretary Stephanie Foster wrote in the direction.
“Continuing to incorporate relevant cyber security risks in the technology lifecycle management process fortifies the Commonwealth’s cyber posture, building readiness and resilience against cyber activities, foreign interference, espionage and sabotage.”
Home Affairs said that particular attention should be paid to older “hardware, software, services, protocols, and/or systems” that underpin so-called systems of government significance, which typically encompass the government’s most critical digital services.
It also urged Commonwealth entities to apply security patches to older systems more rapidly, to narrow any potential window for exploitation.
“Entities should strengthen existing vulnerability and patch management processes for their entire technology estate by recognising the shortened time between vulnerability discovery and exploitation, and by rapidly patching vulnerabilities deemed critical by vendors or internal vulnerability management processes,” Home Affairs wrote.
Further details of the legacy systems push are expected by the mid-October.

